Commentary

George Hulme
 

When It Comes To Getting Hacked, Organizations Fatalistic

According to a British Telecom survey, to be released later this week, 94 percent of the 200 IT professionals surveyed from around the globe expect to suffer a breach.

According to a British Telecom survey, to be released later this week, 94 percent of the 200 IT professionals surveyed from around the globe expect to suffer a breach.My question to the other 6 percent: can I have some of what you are smoking? Of course, much of this boils down to definition of a breach. But it's pretty hard to use the Internet to any degree today without someone, somewhere, in your organization getting nailed with a traffic-sniffing something.

Kelly Jackson Higgins, at our sister site DarkReading reports on the upcoming survey:

In fact, a full 94 percent expect to suffer a successful breach in the next 12 months, according to a new study on ethical hacking to be released by British Telecom (BT) later this week.

More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

The twist: Those who conduct network penetration tests think their chances of getting hacked are less likely than those who don't. Those who pen test estimated their chances of a breach at around 26 percent, while those who don't thought they had a 38 percent chance, according to BT's new 2009 Ethical Hacking study, which polled more than 200 IT professionals worldwide from mid-February through the end of March. Around 60 percent of organizations have budgeted for pen testing, while around 38 percent have not, the study found. Nearly 70 percent allocate 1 to 5 percent of their security budgets for pen testing, 17 percent allocated 6 to 10 percent, and 2 percent set aside 20 percent.

I won't delve into percent of budget dedicated to penetration tests. But when it comes to odds of suffering a breach, I peg that figure much closer to 100 percent. I've watched portions of a number of penetration tests. I've sat across the table from ethical hackers as their clients looked absolutely shocked and mortified when their systems were pwned with tools readily downloadable from the Internet. I've listened in on calls where employers were not only convinced to hand over critical information to the social engineer -- they were terrified that they'd get fired if they didn't.

I've stood next to dumpsters with hackers rummaging through: eventually they pop their heads up and with an almost giddy voice and exclaim: "Look what I found!"

The point is that all of us are hackable. No individual, let alone any organization of any complexity can call itself "HackProof."

Well, they could. But that would only motivate someone who would relatively quickly prove them wrong.

The best we can hope for, in today's sad state of software quality and bolted-on information security tools, is to raise the difficultly level so high that one is not worth the trouble to hack.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links